« Our Company Blogs | Main | Margot Wallström Weblog II »

Firefox Vulnerability

Boing Boing reports an exploit that most browsers, except IE, are vulnerable to.

Shmoo Group demonstrates the exploit, and explains it workings.

Following the proposed fix for Firefox worked for me, though there are reports that it might not work for all.

1) Goto your Firefox address bar. Enter about:config and press enter. Firefox will load the (large!) config page.

2) Scroll down to the line beginning network.enableIDN -- this is International Domain Name support, and it is causing the problem here. We want to turn this off -- for now. Ideally we want to support international domain names, but not with this problem.

3) Double-click the network.enableIDN label, and Firefox will show a dialog set to 'true'. Change it to 'false' (no quotes!), click Ok. You are done.

4) Go check out the shmoo demo again and notice it no longer works. (Chris Smith)

UPDATE:
Firefox has released an update which fixes the problem.

Permalink

Post a comment










Remember personal info?






About

ton2small.jpg Weblog by Ton Zijlstra,
Enschede, Netherlands
I write about knowledge work and management, and the tools and strategies that help us navigate the networked world.
Contacting me is easy and appreciated:
E-mail, Skype, MSN

Syndication:
Full posts
Excerpts

Interdependent Thoughts in Dutch and German:
RSS Nederlands
RSS Deutsch

Archives


March 2009
January 2009
December 2008
November 2008
October 2008
September 2008
August 2008
July 2008
June 2008
May 2008
April 2008
March 2008
February 2008
January 2008
December 2007
November 2007
October 2007
September 2007
August 2007
June 2007
May 2007
April 2007
March 2007
February 2007
January 2007
December 2006
November 2006
October 2006
September 2006
August 2006
July 2006
June 2006
May 2006
April 2006
March 2006
February 2006
January 2006
December 2005
November 2005
October 2005
September 2005
August 2005
July 2005
June 2005
May 2005
April 2005
March 2005
February 2005
January 2005
December 2004
November 2004
October 2004
September 2004
August 2004
July 2004
June 2004
May 2004
April 2004
March 2004
February 2004
January 2004
December 2003
November 2003
October 2003
September 2003
August 2003
July 2003
June 2003
May 2003
April 2003
March 2003
February 2003
January 2003
December 2002
November 2002

Miscellaneous

Technorati Profile

Powered by Movable Type and Qumana
i_use_qumana.png

eXTReMe Tracker


Creative Commons License
This work is licensed under a Creative Commons License.